CVE-2023-49176: WordPress WP Pocket URLs Plugin <= 1.0.2 is vulnerable to Cross Site Scripting (XSS)
Published Dec 15, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Reflected XSS.This issue affects WP Pocket URLs: from n/a through 1.0.2.
Affected Software
2 affected components
CodeRevolution Wp Pocket Urls Wordpress=1.0.0
CodeRevolution Wp Pocket Urls Wordpress=1.0.2
Event History
Dec 15, 2023
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49176?
CVE-2023-49176 is classified as a reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2023-49176?
To fix CVE-2023-49176, update the WP Pocket URLs plugin to version 1.0.3 or later.
3
What versions of WP Pocket URLs are affected by CVE-2023-49176?
CVE-2023-49176 affects WP Pocket URLs versions 1.0.0 through 1.0.2.
4
Can CVE-2023-49176 be exploited without user interaction?
Yes, CVE-2023-49176 can be exploited through crafted URLs without requiring user interaction.
5
What type of attacks can be performed using CVE-2023-49176?
CVE-2023-49176 allows attackers to execute arbitrary JavaScript in the context of the user's browser, leading to data theft or session hijacking.